Staff It Security Engineer

Amplitude Amplitude · Data AI · San Francisco, CA · Engineering : Security

This role focuses on enterprise IT security, specifically designing and building controls for the use of AI tooling and AI-enabled workflows within the corporate environment. It involves managing day-to-day security operations, identity and access management, AI security governance, detection and response, and risk/compliance. The role emphasizes building agentic solutions for security automation and detection, using AI-assisted tools to enhance security operations.

What you'd actually do

  1. Manage and execute day-to-day enterprise security operations across corporate systems, including SaaS security posture, IdP, endpoint, vulnerability management, and access governance, leveraging AI-assisted tooling to accelerate triage, analysis, and documentation at scale.
  2. Execute complex Okta/IdP changes and maintain configurations for auth policies, adaptive MFA, SCIM provisioning, RBAC group management, and lifecycle automation. You will coordinate and execute access reviews across the enterprise to enforce least-privilege remediation, using AI tooling to summarize findings and draft stakeholder follow-ups.
  3. Be crucial in defining AI security by reviewing AI tool permissions, connector/integration configurations, and data-sharing settings. You will build and maintain AI-powered security automation—designing and operating agentic pipelines to automate repeatable security workflows (like app approval triage and access review summarization) and ensuring the security architecture of those pipelines is sound.
  4. Drive detection and response efforts by authoring CrowdStrike IOAs/IOCs, writing SIEM queries, and tuning alerts to reduce noise without losing coverage. You will handle incident triage, scoping, and containment, and produce post-mortem documentation in partnership with a senior engineer.
  5. Conduct vendor and SaaS tool security reviews (intake, risk evaluation, remediation tracking, and sign-off coordination). Produce security metrics and reporting for operational tracking and CISO/exec audiences.

Skills

Required

  • 5–8+ years in enterprise/corporate security
  • hands-on depth in at least two of the following areas: identity (Okta), endpoint (CrowdStrike/Kandji), SaaS security, or detection engineering
  • Ability to regularly write code or scripts (Python, Bash, or similar) to automate reviews, build detections, or debug configuration issues without looping in engineering
  • Genuine curiosity about AI security
  • Excellent communication skills

Nice to have

  • Experience with DLP, SaaS security reviews, or third-party vendor risk processes
  • Familiarity with AI tool governance: acceptable use, tool inventories, and data classification in AI contexts
  • CrowdStrike detection engineering experience (custom IOAs, Falcon LogScale)
  • Familiarity with zero-trust architecture patterns, ZTNA, or CASB/SSPM tooling
  • Python or scripting depth beyond basic automation
  • Prior experience at a high-growth tech company with a small security team and large scope

What the JD emphasized

  • design and build controls that define how Amplitude leverages frontier AI tooling at scale
  • tackling the risks that AI tools and AI-enabled workflows introduce into our environment
  • hands-on with building agentic solutions for detection, response and high-level automation
  • defining AI security
  • build and maintain AI-powered security automation
  • designing and operating agentic pipelines
  • genuine curiosity about AI security is essential